Microsoft SharePoint Server vulnerabilities: known CVEs & security history
Microsoft · Microsoft · 516 tracked CVEs · 15 actively exploited · updated June 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all Microsoft SharePoint Server release lines — 516 in total, with 15 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Microsoft SharePoint Server's current status and the safe version to run.
Known Microsoft SharePoint Server CVEs
Actively-exploited and most-severe first. Showing the top 80 of 516. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2026-20963⚡ exploited | critical | 9.8 | 31% | 2026 |
| CVE-2025-53770⚡ exploited | critical | 9.8 | 100% | 2025 |
| CVE-2023-29357⚡ exploited | critical | 9.8 | 100% | 2023 |
| CVE-2019-0604⚡ exploited | critical | 9.8 | 100% | 2019 |
| CVE-2025-49704⚡ exploited | high | 8.8 | 100% | 2025 |
| CVE-2012-1889⚡ exploited | high | 8.8 | 84% | 2012 |
| CVE-2020-1147⚡ exploited | high | 7.8 | 96% | 2020 |
| CVE-2017-11826⚡ exploited | high | 7.8 | 82% | 2017 |
| CVE-2015-1641⚡ exploited | high | 7.8 | 97% | 2015 |
| CVE-2014-1761⚡ exploited | high | 7.8 | 78% | 2014 |
| CVE-2012-2539⚡ exploited | high | 7.8 | 53% | 2012 |
| CVE-2024-38094⚡ exploited | high | 7.2 | 55% | 2024 |
| CVE-2023-24955⚡ exploited | high | 7.2 | 85% | 2023 |
| CVE-2026-32201⚡ exploited | medium | 6.5 | 24% | 2026 |
| CVE-2025-49706⚡ exploited | medium | 6.5 | 100% | 2025 |
| CVE-2020-1595 | critical | 9.9 | 2% | 2020 |
| CVE-2020-1210 | critical | 9.9 | 2% | 2020 |
| CVE-2024-33879 | critical | 9.8 | 1% | 2024 |
| CVE-2023-21716 | critical | 9.8 | 82% | 2023 |
| CVE-2020-1025 | critical | 9.8 | 6% | 2020 |
| CVE-2019-1205 | critical | 9.8 | 4% | 2019 |
| CVE-2013-1330 | high | 10 | 34% | 2013 |
| CVE-2015-6094 | high | 9.3 | 21% | 2015 |
| CVE-2015-6093 | high | 9.3 | 23% | 2015 |
| CVE-2015-6038 | high | 9.3 | 36% | 2015 |
| CVE-2015-2558 | high | 9.3 | 23% | 2015 |
| CVE-2015-2555 | high | 9.3 | 23% | 2015 |
| CVE-2015-2468 | high | 9.3 | 43% | 2015 |
| CVE-2015-1682 | high | 9.3 | 21% | 2015 |
| CVE-2015-1650 | high | 9.3 | 29% | 2015 |
| CVE-2015-1649 | high | 9.3 | 26% | 2015 |
| CVE-2015-0086 | high | 9.3 | 15% | 2015 |
| CVE-2015-0085 | high | 9.3 | 18% | 2015 |
| CVE-2015-0064 | high | 9.3 | 30% | 2015 |
| CVE-2014-6357 | high | 9.3 | 19% | 2014 |
| CVE-2014-4117 | high | 9.3 | 17% | 2014 |
| CVE-2014-2816 | high | 9.3 | 16% | 2014 |
| CVE-2014-0260 | high | 9.3 | 18% | 2014 |
| CVE-2013-3889 | high | 9.3 | 27% | 2013 |
| CVE-2013-3858 | high | 9.3 | 21% | 2013 |
| CVE-2013-3857 | high | 9.3 | 21% | 2013 |
| CVE-2013-3849 | high | 9.3 | 21% | 2013 |
| CVE-2013-3848 | high | 9.3 | 21% | 2013 |
| CVE-2013-3847 | high | 9.3 | 21% | 2013 |
| CVE-2013-1315 | high | 9.3 | 37% | 2013 |
| CVE-2013-0007 | high | 9.3 | 32% | 2013 |
| CVE-2012-2528 | high | 9.3 | 22% | 2012 |
| CVE-2011-1990 | high | 9.3 | 20% | 2011 |
| CVE-2011-1989 | high | 9.3 | 28% | 2011 |
| CVE-2008-4019 | high | 9.3 | 34% | 2008 |
| CVE-2008-3006 | high | 9.3 | 36% | 2008 |
| CVE-2014-0251 | high | 9 | 13% | 2014 |
| CVE-2020-1523 | high | 8.9 | 2% | 2020 |
| CVE-2026-45484 | high | 8.8 | 1% | 2026 |
| CVE-2026-45659 | high | 8.8 | 2% | 2026 |
| CVE-2026-40365 | high | 8.8 | 1% | 2026 |
| CVE-2026-40357 | high | 8.8 | 2% | 2026 |
| CVE-2026-35439 | high | 8.8 | 2% | 2026 |
| CVE-2026-33112 | high | 8.8 | 2% | 2026 |
| CVE-2026-33110 | high | 8.8 | 2% | 2026 |
| CVE-2026-26114 | high | 8.8 | 2% | 2026 |
| CVE-2026-26106 | high | 8.8 | 1% | 2026 |
| CVE-2026-20947 | high | 8.8 | 18% | 2026 |
| CVE-2025-64672 | high | 8.8 | 1% | 2025 |
| CVE-2025-59237 | high | 8.8 | 2% | 2025 |
| CVE-2025-59228 | high | 8.8 | 1% | 2025 |
| CVE-2025-54897 | high | 8.8 | 18% | 2025 |
| CVE-2025-49712 | high | 8.8 | 17% | 2025 |
| CVE-2025-49701 | high | 8.8 | 1% | 2025 |
| CVE-2025-47172 | high | 8.8 | 1% | 2025 |
| CVE-2025-47166 | high | 8.8 | 12% | 2025 |
| CVE-2025-47163 | high | 8.8 | 11% | 2025 |
| CVE-2025-29794 | high | 8.8 | 4% | 2025 |
| CVE-2024-38018 | high | 8.8 | 46% | 2024 |
| CVE-2024-21318 | high | 8.8 | 31% | 2024 |
| CVE-2023-36764 | high | 8.8 | 2% | 2023 |
| CVE-2023-33160 | high | 8.8 | 5% | 2023 |
| CVE-2023-33159 | high | 8.8 | 1% | 2023 |
| CVE-2023-33157 | high | 8.8 | 44% | 2023 |
| CVE-2023-33134 | high | 8.8 | 3% | 2023 |
436 older / lower-severity CVEs not shown — see Microsoft SharePoint Server's full record.
Is my Microsoft SharePoint Server version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your Microsoft SharePoint Server version → · Monitor Microsoft SharePoint Server for new CVEs →
Microsoft SharePoint Server vulnerabilities — frequently asked
How many known vulnerabilities does Microsoft SharePoint Server have?
IsItPatched tracks 516 CVEs for Microsoft SharePoint Server, 15 of which are actively exploited (CISA KEV). 10 are critical-severity and 291 high-severity. These span every release line — what matters is whether the version you run is affected.
Does Microsoft SharePoint Server have any actively-exploited vulnerabilities?
Yes — 15 Microsoft SharePoint Server CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (7 linked to ransomware). Patch these as a priority.
What is the most severe Microsoft SharePoint Server vulnerability?
Among tracked issues, CVE-2026-20963 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Insecure deserialization weakness.
Is Microsoft SharePoint Server safe to use?
It depends on the version. The latest supported Microsoft SharePoint Server release (16.0.19725.20384) clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Microsoft SharePoint Server security status · Microsoft SharePoint Server end-of-life · actively-exploited CVEs. Always verify against Microsoft's advisories — see our disclaimer.